Authentication and sessions
25 procedures covering login and logout, session expiry and invalidation on logout, password reset flow, remember-me, OAuth and OIDC redirect flow. Out of scope here: penetration testing of auth, SSO vendor configuration, identity provider administration.